Vera, your AI compliance agent, collects evidence through APIs, screenshots, and guided procedures, follows up with owners, and signs every artifact for the auditor you pick. You review and approve.
Animated product demo: Screenata scans your systems, assesses SOC 2 readiness, remediates gaps, collects your review and sign-off, and delivers a signed audit package to your auditor.
AcmeIntegrationsSOC 2 Type II— Ask Vera
Audit cycle · Jan 1 – Jun 30
Scan
Assess
Remediate
Review
Report
Integrations
Connected read-only. Vera scans on a schedule.
Connected 6Available 54 Add
Connected
6
of 60 available
Checks run
0
mapped to controls
Last scan
RunningJust now
Read-only · no agents
IntegrationCategoryStatusChecks
AWSCloudScanningConnected312
OktaIdentityScanningConnected75
GitHubCodeScanningConnected133
Google WorkspaceProductivityScanningConnected58
DatadogMonitoringScanningConnected44
SlackCommunicationScanningConnected28
Vera650 checks across 6 systems
“I really like… the focus on reducing manual work instead of just giving users another compliance dashboard to manage. The AI agent approach… feels more like having an assistant working with you instead of just showing you tasks.”
GRC consultantUsing Screenata with clients
SOC 2 Type II program100%
Scan
Policies
Evidence
Gaps
Pack
Ready for your auditor
From first scan to audit report.
Vera writes the policies, collects the evidence, works through the gaps with your team, and assembles a signed audit package. You approve; your auditor issues the report.
Typical platform$12–25K/yr
Screenata · per framework
$5,988/ year
Every moduleNo per-seat fees
One published price, every module.
$5,988 a year per framework, with no per-seat fees. Year one to SOC 2 Type II runs $22–33K all-in, versus $49–70K doing it yourself on Vanta or Drata.
Every artifact is mapped to a control, dated, and signed, so any auditor can verify it independently. When an enterprise buyer's security team reads it line by line, the proof holds up.
The difference
Other tools track the work. Vera does it.
A dashboard hands you one more list to manage. Vera works alongside you like an assistant: she scans, writes, chases, and files, and you approve what she did.
A GRC dashboardTracks the work
Write the Access Control PolicyAssigned to youYou
Collect Okta MFA evidenceAssigned to youYou
Follow up on overdue evidenceAssigned to youYou
Re-run the S3 encryption checkAssigned to youYou
Answer the prospect's security questionnaireAssigned to youYou
Assemble the audit packAssigned to youYou
Your part: all of it.6 open
Screenata Does the work
Write the Access Control PolicyDone by VeraDone
Collect Okta MFA evidenceDone by VeraDone
Follow up on overdue evidenceDone by VeraDone
Re-run the S3 encryption checkDone by VeraDone
Answer the prospect's security questionnaireDone by VeraDone
Assemble the audit packApprove
Your part:review and approve.5 done · 1 to approve
01 · Policies
Scan first. Then write what you can prove.
Vera assembles context from GitHub, AWS or GCP, your IdP, and existing evidence before a single policy is written. The overpromise checker flags hard commitments unsupported by what she found, before your auditor does.
Policies grounded in real IAM policies, branch protection, and MFA settings
Overpromise detection, the #1 audit failure mode, caught at draft time
All 8 SOC 2 foundational deliverables, right-sized for startup teams
Acme Corp enforces multi-factor authentication through Okta for all administrative access to production systems. verified
Production access is reviewed quarterly by the security team to remove stale entitlements. overpromise
Vera flagged this claim
No quarterly access review evidence found in the last 12 months across Okta and GitHub. Soften to "periodic reviews as needed", or commit to quarterly and let me schedule them.
Soften languageSchedule quarterly review
02 · Evidence
Automate evidence collection beyond APIs.
API integrations are table stakes and cover about 30–40% of a SOC 2. The rest lives in screens and walkthroughs that other platforms hand back to you as a to-do list. Screenata captures those too, and evidence collected once counts toward every framework it satisfies.
01
API Automation
Cloud, code, and identity providers scanned on a schedule. Every check maps to a control and is signed on arrival.
S3 default encryption on all bucketssigned 6:00 AM
Branch protection on mainsigned 6:00 AM
CloudTrail retention 365 dayssigned 6:00 AM
Alerting on production errorssigned 6:00 AM
Controls satisfied
CC6.1Passing
CC6.7Passing
CC8.1Passing
CC7.2Passing
CC1.4Passing
650+ checks · 60+ providers · on a schedule
02
Screenshot Automation
Settings pages and admin consoles with no API, the evidence teams still screenshot by hand. Click the extension, or let a procedure trigger it on schedule. Captured, redacted, quality-checked, signed, filed.
Your team shouldn't have to sign in to one more platform to finish a request. Files dropped in Slack or emailed to your workspace address are filed as evidence and matched to the right test. Nobody has to open the dashboard.
Email your workspace address: attachments are filed as evidence, and Vera replies
Owners get a reminder before work is due and an alert when it's late
Daily freshness checks: fresh, stale at 90 days, expired at 120
Drafted remediation ticket, needs your approval to apply.
Reply to #compliance
04 · Proof
One sentence. One claim. One test. One signed artifact.
Screenata links each policy sentence to the control it satisfies, the test that checks it, and the signed evidence that proves it. Your team can see why a requirement exists and exactly what proves it. Your auditor can verify the artifact outside Screenata.
Trace any policy, claim, control, or test through to its evidence
Each test says what to provide and how your auditor will judge it
A read-only view of controls, evidence, and the signed pack for the auditor you pick.
What auditors need first
“Until we have all the policies in place, the risk assessment completed, system description completed, a timestamped network diagram, a vulnerability scan report, we wouldn’t be able to begin with control testing.”
A SOC 2 auditor
Screenata delivers all eight of those artifacts before your observation window opens. And because two recent collapses broke trust in AI compliance, we answer with architecture, not adjectives.
Credentials never touch our database
Cloud provider keys live in Azure Key Vault, retrieved at scan time, never cached or logged. A breach of us is not a breach of you.
Read-only by construction
No write scopes on your repos or cloud. Source code is scanned in memory and never persisted. We cannot change your infrastructure, by design.
Evidence you can verify yourself
RSA/ECDSA signatures, RFC 3161 timestamps, SHA-256 manifests, BYOK. An open spec and a free verify CLI, no account needed.
$5,988 a year per framework, against a $42–178K year one.
Flat and published at $499/mo per framework for a standard startup audit scope, typically up to 50 employees and one legal entity. Scale & Enterprise is custom-priced for complex programs and includes SAML SSO. The auditor stays independent either way.
You are not paying for a dashboard. You are paying for the work.
SOC 2 Type IIYear one · auditor $7–15K on every path
Excel + DIY
Platform $0 · ~440 hrs
$73–81K
Vanta/Drata + DIY
Platform $12–25K · ~200 hrs
$49–70K
Vanta/Drata + vCISO
Platform $12–25K · vCISO $5–120K · ~120 hrs
$42–178K
Screenata
Platform $6K · 60–80 hrs
$22–33K
Year one to a SOC 2 Type II, four ways
SOC 2 Type IIYear one
Excel+ DIY
Vanta/Drata+ DIY
Vanta/Drata+ vCISO
Screenata
Auditor
$7–15K
$7–15K
$7–15K
$7–15K
Platform
$0
$12–25K
$12–25K
$6K
Consultant
$0
$0
$5–120K
$0
Team time
$66K~440 hrs
$30K~200 hrs
$18K~120 hrs
$9–12K60–80 hrs
Total
$73–81K
$49–70K
$42–178K
$22–33K
FAQ
The questions technical founders ask first.
Concrete architecture, real workflows, and proof over category claims.
What makes Screenata different from Vanta or Drata?
Most compliance platforms track the work: the dashboard shows what's missing and a person goes and does it. Screenata's agent does the work. Vera scans your infrastructure, composes policies from what's real, collects evidence, runs scheduled checks at 6 AM, and delivers everything through Slack, email, GitHub, and your terminal. And where evidence comes from is different: every platform reconstructs it after the work; we're building the one where the work produces it.
Does Vera actually do work without someone clicking buttons?
Yes. Daily 6:00 AM evidence freshness checks, daily 6:15 AM readiness snapshots, weekly Monday cloud and code scans, and annual risk refreshes all run on scheduled jobs; quarterly access reviews are scheduled and orchestrated by Vera, with a human certifying each one. Vera flags stale evidence, drafts delegation messages, scopes remediation, and posts agent reports. You approve actions; you don't run them.
How are policies generated?
Screenata scans first, then writes. We pull context from GitHub, AWS or GCP, your IdP, existing evidence, and your company profile, then generate policies grounded in what we found. The overpromise checker flags hard commitments (like 'quarterly access reviews') we cannot verify in evidence, before you ever ship them to an auditor.
Can auditors trace claims back to proof?
Yes. Each claim in a policy is anchored to a specific sentence and linked to the control test that verifies it. Each test has its evidence submissions, and each submission references a cryptographically signed artifact. An auditor can hover any claim in a policy, see the test that proves it, and verify the evidence package independently with a signed manifest.
What happens to evidence packages?
Evidence exports are tamper-evident: SHA-256 per-file hashes, RSA or ECDSA digital signatures, RFC 3161 independent timestamps, and BYOK support so enterprises can sign with their own keys. We're publishing the format as an open spec with a free verify CLI so anyone can check a Screenata pack without an account.
How do you collect evidence that integrations can't reach?
Three channels, not one. API scans cover about 30–40% of a SOC 2 across cloud, code, and identity providers. The browser extension captures screenshots of settings pages and workflows, redacts sensitive fields, runs a vision quality check, signs the capture, and re-captures it on a schedule. Guided procedures walk a teammate through steps like a backup restore test and record results and attachments as they work. Most platforms only offer the first channel and hand the rest back to you as a to-do list.
How much does SOC 2 cost with Screenata compared to other platforms?
For a company under 50 employees, year one to a SOC 2 Type II runs $22–33K with Screenata, $73–81K in spreadsheets done yourself, $49–70K on Vanta or Drata done yourself, and $42–178K on Vanta or Drata with a vCISO, counting the auditor, the platform, any consultant, and your team's time at $150/hr. The auditor fee is the same on every path, and you choose and pay the auditor directly. Spreadsheets save the licence and cost more than it in hours: your team builds the tracker, gathers every artifact by hand, and re-checks every control each month because nothing monitors it.
No. Every test explains what to provide, which evidence items are required, and how your auditor will judge it, and you can ask Vera about any requirement in plain language. The lineage view traces a policy, claim, control, or test through to the evidence that proves it, so you can see why something is required. When a check fails, it comes with the recommended fix and the steps to apply it, and the finding closes on its own once the nightly re-check passes.
Do we have to collect the same evidence again for each framework?
No. A single test maps to controls in every framework it satisfies, so evidence collected once counts toward SOC 2, HIPAA, and ISO 27001 at the same time. The controls view shows what else each test satisfies, so you can see the reuse instead of taking it on faith.
Can I use Screenata in Slack?
Yes. Files dropped in Slack are saved as evidence and matched to the tests they support, and escalations and SLA alerts post to Slack. You can also email your workspace address: attachments are filed as evidence and Vera replies. The dashboard is there for auditors and deep dives; day-to-day requests get done where your team already works.
Is the evidence Vera produces auditor-ready?
Yes. Every artifact is mapped to specific Trust Services Criteria or HIPAA safeguards, signed with SHA-256 + RFC 3161 timestamps, and traceable from policy claim → control test → submission → vault artifact. Auditors get a structured pack, not a folder of screenshots, and can verify integrity independently with a free CLI. We design the output for what auditors actually look for in fieldwork: completeness, attribution, freshness, and tamper evidence.
Do you work with vCISOs or compliance consultancies?
Yes, Screenata is built to make your practice more profitable, not to replace it. vCISO firms resell or refer Screenata to their clients. Vera absorbs the policy writing, evidence chasing, and status reporting that eats 60% of your hours, so you can take on 3x the clients at the same headcount while keeping the advisory relationship and the margin. You get a firm-admin account across your client tenants. See screenata.com/for-vcisos for the partner program.
Which frameworks do you support?
SOC 2, HIPAA, ISO 27001, ISO 42001, and GDPR. Our control model uses a shared canonical catalog so a single MFA scan satisfies SOC 2 CC6.1 and HIPAA §164.312(d) at the same time, and the same scan maps across the other frameworks you run. You collect evidence once instead of paying for each framework separately.
Connect and see
Your next enterprise deal is going to read the report.
Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, stale evidence, and prioritized next actions before you commit to anything.